Impact
The vulnerability is a missing authorization flaw that lets attackers exploit incorrectly configured access control security levels in the WP Messiah Safe Ai Malware Protection for WP plugin. It allows privileged operations that should be restricted, potentially giving an unauthenticated or low‑privileged user control over sensitive plugin functionality or site administration tasks.
Affected Systems
WP Messiah’s Safe Ai Malware Protection for WP plugin is affected. All deployed instances running versions from the earliest released build up to and including 1.0.20 are vulnerable. Any WordPress site that has this plugin installed and active must be assumed to be at risk.
Risk and Exploitability
The CVSS score of 5.4 classifies the issue as medium severity, while the EPSS score of less than 1% indicates a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote web request that bypasses the plugin’s access checks, allowing an attacker to perform actions otherwise restricted to privileged accounts. Inference: the failure occurs when the plugin serves certain administrative pages or endpoints without validating the requestor’s role or capabilities.
OpenCVE Enrichment
EUVD